PasteZap
🌐 Español
Gratis · Sin cuenta

Gratis · Redes e infraestructura TI

Dimensionamiento de cortafuegos.

Dimensione un cortafuegos de nueva generación: rendimiento de prevención de amenazas, inspección TLS y VPN, sesiones y conexiones nuevas para comparar con las fichas técnicas.

Antes de empezar

Algunos controles técnicos están en inglés. Se admite texto Unicode; los formatos y los idiomas de salida dependen de la herramienta.

Los límites técnicos aparecen en inglés a continuación. Revísalos antes de procesar archivos grandes o utilizar el resultado.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Users and links

Security features enabled

Banking, health and pinned apps are usually excluded.

VPN

Sessions and headroom

Browsers and sync clients keep dozens of connections open.

Threat prevention / threat protection throughput needed1.86 Gbps74,286 sessions
Peak one-direction traffic
1 Gbps
Both directions combined
3.71 Gbps
Some datasheets add both directions; compare with this figure if yours does
TLS inspection throughput
1 Gbps
VPN throughput
1.02 Gbps
Concurrent sessions
74,286
New sessions per second
2,477
WAN port speed
1 GbE
Headroom factor
× 1.86

Compare with the vendor datasheet

Datasheet lineRequiredHow to read it
Firewall throughput (stateful, L4)1.86 GbpsUsually measured with large UDP packets: the most optimistic figure. Never size on this alone.
Threat prevention / threat protection throughput1.86 GbpsThe figure to size on. Check the traffic mix and that logging was enabled in the vendor test.
TLS / SSL inspection throughput1 GbpsOften the lowest datasheet figure; it varies with cipher, key size and session reuse.
IPsec VPN throughput1.02 GbpsCheck whether the figure uses large packets; real VPN traffic mixes small packets.
Concurrent sessions74,286Connection-table size.
New sessions per second2,477Connection setup rate; matters for busy web servers and NAT.
Remote-access VPN users65Licensed or maximum concurrent clients.
Site-to-site tunnels3IPsec tunnel capacity.
  • Vendor-neutral estimate. Datasheet conditions differ between vendors; RFC 9411 and NetSecOPEN describe a common test methodology you can ask vendors about.
  • Plan high availability as a pair of identical units: each unit must carry the full load alone.
  • Inspection throughput falls as features are added; ask the vendor for a figure with your exact feature set enabled.

Cómo usar esta herramienta: Dimensionamiento de cortafuegos

Introduce los datos o selecciona el archivo. Ajusta las opciones, genera el resultado y revísalo antes de copiarlo o descargarlo.

Límites y formatos compatibles

Los datos se procesan en tu dispositivo.

Notas técnicas en inglés

Vendor-neutral estimate; datasheet test conditions differ between vendors. Session counts per device are an assumption you should check against a current firewall. Everything is calculated in your browser; nothing is sent or probed on the network.

Peak traffic (largest direction plus inspected internal traffic) is scaled by growth and divided by the maximum load. TLS throughput applies the encrypted and decrypted shares; sessions are devices × sessions per device; new sessions per second divide sessions by their lifetime.

250 users with 2 devices each on a 1 Gbps link with IPS, application control, anti-malware and TLS inspection need about 1.9 Gbps threat-protection throughput and 74,000 sessions.